Executive brief
Samsung Internet is a mobile web browser used on Samsung devices. A security flaw in versions prior to 30.0.0.39 could allow a malicious application installed on the same device to bypass security checks and access sensitive user information. This could lead to the exposure of private browsing data or other personal information stored within the browser.
Technical details
An improper authorization vulnerability exists in the Samsung Internet browser application. The flaw allows a local attacker with low privileges to bypass authorization mechanisms and gain access to sensitive information. The vulnerability is triggered locally on the device and does not require user interaction. Samsung has addressed this issue in version 30.0.0.39 by implementing proper authorization checks. The CVSS 4.0 score of 6.3 reflects a medium severity impact, primarily affecting the confidentiality of local data.
Affected products
- Samsung Internet prior to 30.0.0.39
Timeline
- 2026-06-02: advisory: Samsung published the initial security bulletin.
- 2026-06-05: disclosed: CVE record published and NVD dataset updated.